Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

gcs-connector- CVE #1221

Open
sdkaarush opened this issue Jul 10, 2024 · 0 comments
Open

gcs-connector- CVE #1221

sdkaarush opened this issue Jul 10, 2024 · 0 comments

Comments

@sdkaarush
Copy link

sdkaarush commented Jul 10, 2024

gcs-connector-hadoop3-2.2.23 (https://repo1.maven.org/maven2/com/google/cloud/bigdataoss/gcs-connector/hadoop3-2.2.23/gcs-connector-hadoop3-2.2.23-shaded.jar)
This is CVE is also there in the latest version of gcs-connector-hadoop3-2.2.24
has CVE related to Jackson-core-2.13.4

Screenshot 2024-07-10 at 6 38 19 PM Screenshot 2024-07-10 at 6 40 54 PM

Dependency tree for gcs-connector-hadoop3-2.2.23:

Screenshot 2024-07-10 at 6 41 16 PM

can you please upgrade the jackson-core version to at least 2.15.0?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant